
wp2shell
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

Unauthenticated Privilege Escalation via Account Takeover


Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Unauthenticated Privilege Escalation to Administrator via Role Form Field

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

exploit of CVE-2022-0847 which directly remove password of the root account

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Security Research


Python script for Kerberoasting with targeted ACL abuse: sets temporary SPNs on users without them, extracts Kerberos hashes, then removes the SPN.…

CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp

CVE-2023-6654 EXP

Leak of any user's NetNTLM hash. Fixed in KB5040434

WallEscape vulnerability in util-linux